NATO quietly ran one of its most important cyber exercises of the decade. And almost nobody outside the defense world noticed. Cyber Coalition 2025 wrapped up last week in Tallinn, and the storyline was not the usual “hackers stole data” thriller. This time, NATO simulated a full-blown “Space to Soil” crisis. A fictional country named Icebergen lost power grids, satellites, troop tracking, and national infrastructure because attackers compromised low-earth-orbit assets and corrupted timing data. This is not science fiction. This is the future of conflict. Attackers didn’t jam satellites. They injected false telemetry into LEO constellations. That poisoned the ground GPS timing. That desynchronized the electrical grid. Safety relays tripped. Hospitals, transport networks, and military units lost their bearings. And when defenders tried to restore from backups, they found the backups already corrupted weeks earlier. The nightmare scenario we keep warning boards about. The real test was not technology. It was speed. Could cyber teams, energy operators, military space commands, and lawyers coordinate fast enough across 29 nations to stop a timing attack in orbit from becoming a blackout in Europe. NATO wanted to see if a defender in Estonia could talk to a space operator in France and get ahead of a grid collapse in Germany. Cyber. Space. Energy. Law. Politics. All converging at once. Welcome to modern war. And here is the part CISOs should pay attention to. The scenario treated civilian infrastructure as part of the battlespace. Timing manipulation is a far bigger threat than ransomware. Your backups may already be poisoned long before an attack triggers. And your coordination with government agencies will matter as much as your tech stack. The military is training for this. Most companies are not. Stay alert out there. The next conflict will not start with a missile. It will start with a timing fault. 🔔 Follow Michael Reichstein for more cybersecurity and AI leadership insights ♻️ Useful? Share to help others, and join me on Substack for the unfiltered version: https://lnkd.in/gKDVq944 #cybersecurity #nato #aigovernance #cisoleadership #criticalinfrastructure #geopolitics #space #cyberresilience #riskmanagement #technology
Impact of Cyber Warfare on Modern Battlefields
Explore top LinkedIn content from expert professionals.
Summary
Cyber warfare is reshaping modern battlefields by integrating digital attacks and disruptions directly into military operations, often targeting both military and civilian infrastructure. This new form of conflict goes beyond traditional fighting, introducing threats like data manipulation, coordinated hacking, and the blending of physical and digital attacks that impact society as a whole.
- Prioritize digital defense: Build robust cybersecurity strategies that protect not just military assets, but also civilian infrastructure and essential services.
- Strengthen rapid coordination: Develop quick-response plans that connect cyber teams, energy operators, legal experts, and government agencies to handle emerging threats in real time.
- Expand battlefield awareness: Prepare both technology and personnel to operate in environments where digital disruptions can occur before any physical conflict starts, ensuring resilience and adaptability.
-
-
War on the Rocks lays out a sobering but necessary thought exercise: what if China got the first move right in a Taiwan scenario—not kinetically, but electromagnetically and digitally? Cyber, electronic warfare, and information denial aren’t shaping operations anymore—they are the main effort. The ability to disrupt U.S. logistics, blind command and control, and fracture operational coherence before the first shot is fired is not theoretical. It’s the opening move. The article highlights a critical truth: we can’t assume access, bandwidth, or perfect situational awareness in the next fight. And if we don’t architect resilience into our weapon systems, data pathways, and sensing infrastructure now, we will be rebuilding it under fire. This is where platforms need to be more than connected—they need to be self-aware, cyber-resilient, and capable of surviving in degraded, contested environments. Awareness isn’t just about seeing the battlefield—it’s about staying in the fight when the lights flicker. https://lnkd.in/gmfBeVmN #CyberResilience #ElectronicWarfare #BattlefieldAwareness #ContestedLogistics #OperationalTechnology #DefenseInnovation #Shift5 #TaiwanScenario #MissionAssurance
-
Cyber Warfare Merges with Kinetic Conflict in the Iran War The Iran conflict is demonstrating a new phase of warfare where digital operations are tightly synchronized with physical attacks. A recent incident highlights this convergence, as civilians fleeing missile strikes received deceptive messages that appeared to offer safety information but instead installed spyware, granting attackers access to personal devices. This operation reflects a high level of coordination between cyber and military actions. The timing of the phishing messages, delivered during active missile strikes, suggests an intentional effort to exploit moments of vulnerability. Once installed, the spyware enabled access to sensitive data, including location, communications, and device controls, effectively turning personal smartphones into intelligence assets. This tactic illustrates how cyber tools are being used not just for espionage, but as force multipliers within active combat scenarios. The broader campaign underscores how nations are integrating cyber capabilities to offset conventional military limitations. Iran and its affiliates are leveraging hacking, disinformation, and emerging technologies such as artificial intelligence to expand their operational reach. Targets are no longer limited to military infrastructure but include civilians, healthcare systems, and critical services, blurring the lines between battlefield and society. The implications are profound. Modern conflict is no longer confined to physical domains but extends deeply into digital ecosystems that underpin daily life. This evolution demands a rethinking of defense strategies, where cybersecurity becomes as critical as traditional military readiness. Protecting civilian infrastructure, strengthening digital resilience, and developing rapid response mechanisms will be essential as cyber-physical warfare becomes a defining characteristic of future conflicts. I share daily insights with tens of thousands followers across defense, tech, and policy. If this topic resonates, I invite you to connect and continue the conversation. Keith King https://lnkd.in/gHPvUttw
-
The kinetic dimension of the Iran war dominates front pages. But a parallel conflict — less visible, arguably more consequential for long-term U.S. security — is accelerating in cyberspace, and the scale is only now becoming clear. The Utah-based security firm DigiCert has tracked approximately 5,800 cyberattacks by nearly 50 groups tied to Iran since the war began on February 28. While the majority targeted American and Israeli entities, attacks also struck networks in Bahrain, Kuwait, Qatar, and other regional states. The Washington Post reported on March 29 that the conflict has become a case study in how targeting of data centers reflects cyber operations fully integrated into kinetic warfare. Two incidents illuminate the sophistication of what Iran is executing. First, the Handala Team's attack on Stryker, the Michigan-based medical technology giant: hackers exploited an internal administrator account and used Microsoft Intune to remotely wipe over 200,000 devices while claiming to exfiltrate 50 terabytes of data. This was not a ransomware play — it was a destructive wiper attack framed explicitly as retaliation for an airstrike on an Iranian school. Second, and more chilling from an intelligence tradecraft perspective: during an Iranian missile strike, some Israeli Android users received texts offering links to bomb shelter information. The links instead deployed spyware providing real-time access to device cameras, locations, and personal data. This is the convergence of kinetic and cyber operations that intelligence professionals have theorized about for years — executed at scale. Cybersecurity experts warned on March 29 that "there are a lot more attacks happening that aren't being reported." The implication is that the visible attacks represent a fraction of the actual campaign. Iran is compensating for its conventional military disadvantage by waging an asymmetric conflict across the digital domain, targeting supply chains, hospitals, ports, and critical infrastructure that the American public does not typically associate with a war in the Middle East. This is the dimension of the conflict most likely to persist long after the bombs stop falling. Follow my Substack 'Fault Lines': williamusher.substack.com | 'Intelligence at the Edge' on Apple Podcasts: https://lnkd.in/ezJCHH_X #CyberSecurity #IranWar #AI #NationalSecurity #IntelligenceCommunity
-
What does it look like when a nation-state attacks you, but nobody fires a shot? An article/report from the LBC in the UK exclusive lays out what those of us in the intelligence and cybersecurity community have been warning about for years: Iran's retaliation against the West won't look like a battlefield. It'll look like disrupted financial services, grounded flights, paralyzed supply chains, and media interference. Welcome to grey zone warfare. After Iran fired missiles toward the joint US-UK base at Diego Garcia, Britain (and others) moved from "interested observer" to "active target" in Tehran's calculus. Iran's foreign minister has publicly stated that allowing the US to use British bases amounts to participation, and that Iran reserves its right to respond. That response probably won't be conventional warfare. It'll be cyber warfare (but let's be honest, that has already been underway it will just ramp up.) During my career at the FBI, including years spent working counterintelligence and tracking nation-state cyber operations, I watched this playbook develop in real time. Iran doesn't need to match Western military capability. They just need to create enough chaos to erode public confidence and strain critical infrastructure. Here's what grey zone cyber warfare actually looks like: 🔹 DDoS attacks that flood government and financial systems until they go dark, cheap, deniable, and devastatingly effective 🔹 Supply chain compromises where a single breach cascades across industries within hours 🔹 Drone incursions near critical infrastructure, an airport runway shutdown ripples across an entire economy in minutes 🔹 Proxy operations through hacktivist groups and individuals who may not even know who's pulling the strings 🔹 Disinformation campaigns that blur the line between state action and grassroots activity until no one knows what's real. The cybersecurity experts quoted in this article are right: we should assume much of this activity is already underway. Not coming. Happening. This isn't just a UK problem. If you're in logistics, financial services, energy, critical infrastructure, or government, on either side of the Atlantic — your threat model (assuming you are paying attention to the threats targeting you) just changed. The organizations that survive grey zone conflict are the ones that prepared before the headlines caught up. Knowledge is Protection. (Article in comments) #CyberSecurity #GreyZoneWarfare #Iran #NationStateThreats #CriticalInfrastructure #TheCyBUrGuy #KnowledgeIsProtection #CyberThreats #Geopolitics #ThreatIntelligence
-
𝗧𝗵𝗲 𝗦𝘁𝗮𝗿𝗹𝗶𝗻𝗸 𝗧𝗿𝗮𝗽 𝗧𝘂𝗿𝗻𝗲𝗱 𝗖𝗼𝗺𝗺𝘀 𝗜𝗻𝘁𝗼 𝗖𝗼𝗼𝗿𝗱𝗶𝗻𝗮𝘁𝗲𝘀 The Times’ reporting on Ukraine’s Starlink deception operation shows something far more important than a clever hack. It shows how modern warfare is collapsing the boundary between cyber access, battlefield intelligence and physical targeting. 🛰️ According to Maxim Tucker’s investigation, tens of thousands of Starlink receivers had been smuggled into Russia through third countries and used by Russian forces to improve drone control, communications and battlefield coordination. When registration controls were introduced for Starlink terminals on Ukrainian territory, unregistered Russian systems were suddenly cut off, and desperate soldiers started looking for ways to regain access. That is where Ukraine’s cyberwarfare specialists reportedly turned dependency into vulnerability. Acting like technical support, they used staged requests and an AI-enabled chatbot to extract data from Russian users, moving from serial numbers to GPS coordinates. Those coordinates were then passed to Ukraine’s Ministry of Defence or directly to nearby brigades, turning Russian attempts to restore connectivity into intelligence on headquarters, command posts and drone pilot positions. ⚠️ This is the real #CyberWarfare lesson. The decisive effect was not “hacking Starlink” in the Hollywood sense. It was exploiting trust, urgency and operational dependency until the enemy voluntarily revealed the location of the very systems keeping its kill chain alive. For #DroneWarfare, the implication is sharp. Connectivity is now combat power, but every connected system also creates a signature, a dependency and a deception surface. The more armies rely on satellite terminals, apps, digital maps, chatbots, cloud tools and improvised networks, the more every workaround becomes a possible trap. 🎯 Ukraine’s advantage here is not just technical skill. It is the ability to fuse cyber deception, human behaviour, frontline intelligence and strike assets quickly enough for information to become firepower. That is what makes this case so important: the keyboard did not replace the drone, it helped point the drone. 𝘛𝘩𝘦 𝘯𝘦𝘸 𝘣𝘢𝘵𝘵𝘭𝘦𝘧𝘪𝘦𝘭𝘥 𝘥𝘰𝘦𝘴 𝘯𝘰𝘵 𝘴𝘦𝘱𝘢𝘳𝘢𝘵𝘦 𝘤𝘰𝘮𝘮𝘴, 𝘤𝘺𝘣𝘦𝘳 𝘢𝘯𝘥 𝘴𝘵𝘳𝘪𝘬𝘦; 𝘪𝘵 𝘵𝘶𝘳𝘯𝘴 𝘦𝘢𝘤𝘩 𝘰𝘯𝘦 𝘪𝘯𝘵𝘰 𝘵𝘩𝘦 𝘰𝘵𝘩𝘦𝘳.
-
When countries enter armed conflict, the cyber threat landscape shifts for everyone. There are some parallels we can draw with the early stages of Russia’s invasion of Ukraine, although conflict always brings unpredictability. At the outset of the Ukraine invasion, global ransomware activity dropped as many regional cyber actors redirected their focus towards the conflict. This reflected the reality that many ransomware groups were based in Russia, Ukraine, or neighbouring states such as Belarus, and their priorities became more nationalistic. Some groups even fractured along national lines, as seen with Conti. The dip was brief though, and most groups soon returned to criminal operations, with non‑regional actors quickly filling any gaps. While the Middle East does not have the same concentration of ransomware operators, it is reasonable to expect regional groups to adjust their targeting in support of the current conflict. During the early days of the Ukraine war, we also saw disruptive activity against organisations such as ViaSat, a satellite communications provider used by the Ukrainian military. The attack aimed to undermine defensive coordination but caused wider collateral disruption across Europe, including outages at German windfarms that relied on ViaSat for monitoring. Although the current conflict has so far been dominated by missiles, drones and air power, recent reporting indicates the United States has used cyber operations in other theatres to neutralise air defence systems. It would not be surprising to see similar tactics here. This raises the risk of unintended spillover when military and civilian systems are tightly linked, including where defence manufacturers provide remote support. A significant strategic risk lies in understanding Iran’s historic approach to retaliation. Iran has previously responded to international pressure with deliberate, proportional actions. For example, following United States‑led economic sanctions in the early 2010s, Iran launched DDoS attacks against the US financial sector, its own form of economic retaliation. Over the weekend, Iran carried out drone and missile strikes against regional states it believes facilitated the US‑Israeli operation, alongside statements promising revenge for the death of Ayatollah Khomeini. For now, its response remains kinetic and focused on regional US assets that fall within missile and drone range. However, if the United States were to use offensive cyber capabilities against Iran, particularly if civilian infrastructure were affected, Iran may seek a proportional response against US civilian systems. And, of course, it is worth noting that cyber operations can reach far beyond the range of conventional weapons. #OperationEpicFury #Iran #CyberThreat #CyberSecurity
-
The article argues that Ukraine has brutally exposed how atrophied U.S. emissions control (EMCON) skills have become, showing that simply transmitting—regardless of encryption—can reveal a unit’s location and lead to destruction within minutes. These are not new lessons: during the Cold War, U.S. forces trained to fight Russia on a transparent battlefield, practicing radio silence, dispersion, and disciplined communications, but two decades of counterinsurgency allowed those skills to decay as constant connectivity became the norm. Drawing on Ukrainian battlefield examples and U.S. Army training center rotations, the author shows how peer adversaries now use drones and electronic warfare to detect transmission patterns and rapidly cue artillery, killing units that rely on frequent radio traffic, clustered antennas, Wi-Fi, and personal devices. Units that survive are those that relearn EMCON—transmitting less, hiding antennas, shrinking command posts, and accepting discomfort. The core warning is simple: EMCON is a perishable combat skill we once mastered, have largely forgotten, and must rapidly rebuild before the next war forces us to relearn it under fire.
-
What Venezuela revealed about the future of Electronic Warfare Last week’s operation in Venezuela was not just a raid. It was a real-world demonstration of Battlefield Information Dominance, one of the Pentagon’s critical technology priorities, and a clear signal of how modern conflict is evolving. Most of the public conversation has focused on the operators and the kinetic execution. That part of the story is important, but it is not the full picture. The real advantage was invisible. The battlefield was shaped long before kinetic forces moved What made the operation possible was not scale or speed alone. It was control of information across domains. ✈️ Air. 🛰️ Space. 🛜 Cyber. What the DOW refers to as the electromagnetic spectrum. These were not used in isolation. 🚫 📶 They were layered and synchronized to degrade the Venezuelan military’s ability to see, communicate, and respond. Modern conflict is shifting away from the outright destruction of forces. Increasingly, it is about denying coherence and slowing decision-making at critical moments. ⚡ Electronic Warfare was the quiet enabler Electronic Warfare did not dominate headlines, but it set the conditions for subsequent developments. 📡 Radar systems did not simply fail. They were confused. 📞 Communications did not drop by chance. They were disrupted. ☢️ Air defenses were not overwhelmed. They were blinded. This is what effective control of the electromagnetic spectrum looks like. Sensors produce false returns. Command chains hesitate. Defenders react late or not at all. By the time kinetic forces were in motion, the advantage already existed. 💡 Information dominance is an active process There is still a tendency to equate information advantage with better intelligence or more data. That view is outdated. What we saw instead was active shaping of the environment: 🎯 Persistent sensing to understand patterns and intent. 🎯Cyber effects to fracture coordination. 🎯Electronic Warfare to suppress, deceive, and delay responses in real time. The objective was not total blackout. It was selective disruption applied at the right moment to create decision advantage. That distinction matters. 🔑 The strategic takeaway Adversaries today do not rely on single systems. They build redundancy and layered defenses. The answer is not more platforms. The answer is integration. The force that wins is the one that sees first, understands first, and acts first, while denying the same to its opponent. Why this matters beyond Venezuela This operation should not be viewed as an exception. It is a preview. Future conflicts, especially against capable or asymmetric adversaries, will hinge on control of the electromagnetic and information environment. ⚔️ Electronic Warfare is no longer a supporting capability. It is foundational. Wars are not won by platforms alone. They are won by turning information into advantage and advantage into action.
-
We all have a front-row seat to the future of warfare, and I’m not just talking about AI. Consider Ukraine and Iran. Every contested environment today shares a common thread: cyber is not merely supporting the fight; it is shaping it. Cyber disruptions slow decision-making, exploit identity to gain access, and create operational paralysis. However, the most concerning aspect is the speed at which these cyber activities are occurring. According to CrowdStrike’s latest Global Threat Report, the adversary is accelerating faster than organizations can respond. Here are some alarming statistics: - 79% of attacks are now malware-free; they use valid credentials and trusted access. - Breakout time can be as fast as 27 seconds from entry to lateral movement. - Identity is involved in approximately 35% of cloud intrusions. - China-linked cyber activity has increased by 150%. Let these statistics sink in. This is no longer about perimeter defense or even malware. It is about exploiting trust at machine speed. This raises a crucial question and demands deep discussion within the United States Department of War: Are we operating with independent, adversary-driven visibility across our environment, or are we relying solely on what we’re being told? Adversaries don’t care about our architectural diagrams or contract agreements. They are: - Moving across identity, endpoints, and cloud simultaneously. - Exploiting the seams between systems and tools. - Leveraging speed, automation, and AI to stay ahead. However, if detection is tied to the same systems being targeted, who is validating the truth? This conversation needs to shift from “Do we trust the platform?” to “Can we independently verify what is happening—at the speed of the adversary?” In Ukraine, delays have cost lives and territory. In the Middle East, they shift regional stability and shape the narrative. And in the next fight, they could cost mission success. This isn’t about replacing existing systems but ensuring we have the VISIBILITY, VALIDATION, and SPEED to combat these threats. We can take action today or face the consequences tomorrow. #CyberWarfare #ZeroTrust #CyberSecurity #NationalSecurity #IdentitySecurity #OperationalResilience #ThreatIntelligence #DepartmentOfDefense #DecisionAdvantage
Explore categories
- Hospitality & Tourism
- Productivity
- Finance
- Soft Skills & Emotional Intelligence
- Project Management
- Education
- Leadership
- Ecommerce
- User Experience
- Recruitment & HR
- Customer Experience
- Real Estate
- Marketing
- Sales
- Retail & Merchandising
- Science
- Supply Chain Management
- Future Of Work
- Consulting
- Writing
- Economics
- Artificial Intelligence
- Employee Experience
- Healthcare
- Workplace Trends
- Fundraising
- Networking
- Corporate Social Responsibility
- Negotiation
- Communication
- Engineering
- Career
- Business Strategy
- Change Management
- Organizational Culture
- Design
- Innovation
- Event Planning
- Training & Development